What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Before connecting an AI client to a WordPress MCP server, limit what the server exposes, enforce permissions inside each ability, and connect with a dedicated WordPress identity. Then choose a transport suited to the deployment, protect its credentials, and monitor what the client does. An MCP client can discover and execute the WordPress functionality exposed to it, so each public ability should be treated as part of your site’s attack surface.

1. Inventory the abilities the server exposes

The WordPress MCP Adapter maps WordPress Abilities into MCP primitives. In its default server, an ability is exposed only when its registration explicitly marks it public for MCP access with meta.mcp.public. Review those registrations before connecting a client; setting this flag indiscriminately can make more functionality available than the task requires. See the WordPress MCP Adapter walkthrough and the WordPress MCP tutorial.

For every ability marked public, record what it can read, what it can change, and which WordPress capability should authorize it. Keep the exposed set as small as possible. If the client only needs contextual information, consider whether an MCP resource is more appropriate than an executable tool.

  • Remove MCP exposure from abilities the client does not need.
  • Separate read-only operations from actions that create, edit, publish, or delete content.
  • Do not expose powerful or destructive operations to an unaudited client.

2. Enforce permissions inside every ability

Visibility is not authorization: hiding a tool from a client does not replace server-side permission checks. Each ability should use a careful permission_callback and check the minimum WordPress capability needed for that operation. The WordPress guidance gives manage_options and edit_posts as examples and warns against using __return_true for destructive operations. As Jonathan Bossenger puts it, “Each ability should check the minimum capability needed (manage_options, edit_posts, etc.).”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Match the check to the action rather than granting a broad capability by default. A read operation and a content-deletion operation should not share permissive authorization merely because they are exposed through the same MCP server. Validate authorization at the point where the ability runs, even if you expect only a particular client to call it.

3. Use a dedicated, constrained WordPress identity

Connect the MCP client with a dedicated WordPress user or role that has only the capabilities required for its assigned work. This gives the connection a distinct identity to audit and makes its authority easier to constrain than a broad administrator account. Do not give an unaudited AI client access to powerful abilities through an administrator identity.

Rank #2
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Decide which operations that account genuinely needs before granting capabilities. If the use case can remain read-only, keep it that way—especially for an endpoint reachable over HTTP.

4. Choose STDIO or HTTP for the deployment

Transport is an architectural choice, not a security guarantee. The WordPress MCP Adapter walkthrough describes STDIO through WP-CLI for local development and HTTP through the @automattic/mcp-wordpress-remote proxy for publicly accessible WordPress sites or other non-STDIO connections.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
GoTrust Idem Key A USB Security Key NFC FIDO2 L2 Certified
  • Protect accounts with USB-A & NFC 2FA security key. Hardware-based authentication blocks phishing, credential theft & unauthorized access across cloud, enterprise & personal platforms.
  • FIDO2 Level 2 certified Security Key. TAA compliant and supports Apple ID, Microsoft Azure/Entra ID, AWS, Google, Facebook, Salesforce, DUO & more. Works with Chrome, Safari & Edge across major OS.
  • Plug & play USB-A Security Key with NFC tap login. No software, drivers or batteries required. Works with Windows PC, MacBook, iPhone, Android & Chromebook for fast, secure authentication.
  • Built with FIPS 140-2 Level 3 secure element for advanced encryption. Trusted by IT teams, healthcare, education & government for secure authentication and identity protection.
  • IP68 waterproof, dustproof & crush-resistant design. Supports FIDO2, U2F, OTP, PIV, Mini Driver & smart card login. Durable USB security key for long-term enterprise and daily use.
Choice Described use Security consideration
STDIO through WP-CLI Local development Keep the client and server setup appropriate to the local environment and limit the WordPress identity to the required capabilities.
HTTP through the remote proxy Publicly accessible WordPress sites or non-STDIO connections The endpoint is remotely reachable, so deliberately configure authentication and limit what it can do. Prefer read-only abilities where the task allows.

The available WordPress guidance identifies these transport patterns but does not establish a universal firewall, proxy, TLS, or network-allowlist configuration. Choose those controls for your own hosting and network design rather than assuming that selecting HTTP or STDIO secures the deployment by itself.

5. Protect credentials and know how to revoke them

The Adapter walkthrough identifies WordPress application passwords as the default authentication method and notes that OAuth or other methods can be implemented. Treat whichever credential your deployment uses as sensitive: store it securely and ensure client configuration is updated when a credential is replaced.

Rank #4
SecuX PUFido® Drive Clife Key USB C Security Key with PUF Technology and Built in Flash Drive, FIDO2 U2F Certified Hardware Rooted Unclonable Security for Passwordless Login and 2FA Authentication (1)
  • Hardware-Rooted Security with PUF Technology – PUFido Drive Clife Key uses Physical Unclonable Function technology to generate a unique, hardware-based identity that cannot be duplicated, delivering stronger resistance against tampering and cyber attacks than conventional security keys.
  • FIDO2 Certified Phishing-Resistant Protection – Fully compliant with FIDO2/U2F standards, enabling secure passwordless login and two-factor authentication to help protect accounts from phishing and credential theft.
  • Security Key + Flash Drive in One Device – Combines a FIDO security key with a built-in USB flash drive, allowing you to carry files and a hardware authentication key together in a single compact device.
  • Easy to Use & Portable – Compact USB-C design fits easily on a keychain or in a pocket. Simply plug in the Drive Clife Key to authenticate or access stored files with no extra software required.
  • Universal Compatibility – Works with hundreds of FIDO2/U2F compatible services and supports Windows, macOS, Linux, iOS, Android, and other major platforms.

Application-password handling can differ by service. The WordPress.org MCP handbook says that, for its authorization flow, a generated application password is shown only once; authorizing again replaces the previous password, and access can be revoked in account security settings. Those details apply to that service’s flow, not automatically to every WordPress MCP deployment. Check the authorization method used by your own server, and revoke the corresponding credential when the client no longer needs access.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

6. Monitor usage and review AI-generated work

Log and monitor MCP usage so you can review what the client called and investigate errors. Where the site has an established monitoring stack, use compatible error and observability handlers rather than leaving MCP activity disconnected from operational review.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
SecuX PUFido USB-C Security Key with PUF Technology, FIDO2/U2F Certified, Hardware-Rooted Unclonable Security for Passwordless Login and 2FA Authentication
  • A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
  • FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
  • Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
  • Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
  • Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.

Review the client’s actions and outputs under your normal WordPress change process. For plugin development, the WordPress.org handbook says AI-assisted submissions receive the same review as other submissions and that developers remain responsible for reviewing generated work. AI assistance does not transfer that responsibility to the client or the MCP server.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.